Understand RHEL lifecycle phases and mitigate risks when RHEL 7 enters the Extended Life phase by upgrading or purchasing an ELS subscription.
RHEL lifecycle overview
Red Hat Enterprise Linux (RHEL) is an enterprise-grade, open source Linux operating system widely used in server and data center environments. See Red Hat Enterprise Linux Life Cycle.
RHEL public images on Alibaba Cloud are sourced from Red Hat, with technical support jointly provided by Alibaba Cloud and Red Hat. On June 30, 2024, RHEL 7 transitioned from Maintenance Support to Extended Life phase for four years. The following table lists the lifecycle phases of RHEL.
|
Version
|
Release date
|
Mainstream Support phase
|
Extended Support
End Date
|
|
Full Support
End Date
|
Maintenance Support 1
End Date
|
Maintenance Support 2
End Date
|
|
Maintenance Support End Date
|
|
Red Hat 10
|
2025-05-20
|
2030-05-31
|
2035-05-31
|
2038-05-31
|
|
Red Hat 9
|
2022-05-18
|
2027-05-31
|
2032-05-31
|
2035-05-31
|
|
Red Hat 8
|
2019-05-7
|
2024-05-31
|
2029-05-31
|
2032-05-31
|
|
Red Hat 7
|
2014-06-10
|
2019-08-06
|
2020-08-06
|
2024-06-30
|
2029-05-31
|
|
Red Hat 6
|
2010-11-10
|
2016-05-10
|
2017-05-10
|
2020-11-30
|
2024-06-30
|
|
Red Hat 5
|
2007-03-15
|
2013-01-08
|
2014-01-31
|
2017-03-31
|
2020-11-30
|
|
Red Hat 4
|
2005-02-14
|
2009-03-31
|
2011-02-16
|
2012-02-29
|
2017-03-31
|
Impacts of the RHEL 7 Extended Life phase
During the Extended Life phase, Red Hat no longer provides vulnerability fixes, security patches, hardware enablement, or root cause analysis for RHEL 7. Support is limited to existing installations.
Recommended solutions
Evaluate the impact based on your business needs. Applications scheduled for decommission can disregard this event. Private network applications face manageable risk. Internet-facing applications that require high stability and security must evaluate end-of-service risks and develop a response plan.
For new services
Do not use RHEL 7 images to create new ECS instances. Instead, choose an operating system in a mainstream support phase, such as RHEL 8 or RHEL 9.
For existing applications
-
Short term: purchase an ELS subscription for RHEL 7 to continue receiving security updates and bug fixes.
-
Long term: upgrade to a later version (recommended). Perform an in-place upgrade from RHEL 7 to RHEL 8, or from RHEL 8 to RHEL 9, using your existing RHEL 7 subscription. Newer versions provide additional security updates, new features, and broader hardware and software compatibility.
Upgrade to a later version
An in-place upgrade upgrades your RHEL system from one major version to another (for example, RHEL 7 to RHEL 8) without a fresh installation. It retains your existing applications, configurations, and data while ensuring continued security updates and technical support.
Red Hat provides the Leapp tool for in-place upgrades with pre-upgrade checks. You can perform the upgrade by remotely logging on to an ECS instance.
-
For a RHEL 7 system from an Alibaba Cloud Marketplace image (with a RHEL 7 subscription) or a self-imported RHEL 7 image with an Alibaba Cloud subscription, see Upgrade from RHEL 7 to RHEL 8.
-
For a RHEL 7 system with a subscription purchased directly from Red Hat, see Upgrading from RHEL 7 to RHEL 8.
Purchase an Extended Life Cycle Support (ELS) subscription
The RHEL Extended Life Cycle Support (ELS) Add-On provides critical security fixes and urgent bug fixes during the Extended Life phase. ELS applies only to RHEL 7.9 and is valid until June 30, 2028. To purchase RHEL 7 ELS on Alibaba Cloud, see Purchase a software license for an ECS instance.
RHEL 7 ELS Add-on pricing:
-
1 to 8 vCPUs: monthly subscription (USD 5.24 per vCPU per month), yearly subscription (USD 54.52 per vCPU per year), and pay-as-you-go (USD 0.0084 per vCPU per hour)
-
9 to 127 vCPUs: monthly subscription (USD 3.93 per vCPU per month), yearly subscription (USD 40.89 per vCPU per year), and pay-as-you-go (USD 0.006 per vCPU per hour)
-
128 vCPUs or more: monthly subscription (USD 3.41 per vCPU per month), yearly subscription (USD 35.44 per vCPU per year), and pay-as-you-go (USD 0.0048 per vCPU per hour)
FAQ
After RHEL 7 enters the ELS phase, am I required to purchase a RHEL ELS Add-on subscription for my RHEL 7 instances?
No. The ELS subscription is optional and depends on your business needs.
After RHEL 7 enters the ELS phase, will my instances be stopped if I do not purchase a RHEL ELS Add-on subscription?
No. Your instances continue to run. However, without the ELS subscription, you cannot obtain security updates and patches from Red Hat, which leaves your instances unprotected.
After RHEL 7 enters the ELS phase, can I renew my instances as normal if I do not purchase a RHEL ELS Add-on subscription?
Yes. Subscription RHEL instances can be renewed as usual. See Renew a subscription instance.
After RHEL 7 enters the ELS phase, will I still be charged license fees for RHEL images?
RHEL 7 instances still require a RHEL license after entering the ELS phase. Your subscription provides the following:
-
Published software updates and security patches for RHEL 7.
-
RHEL 8 software packages for in-place upgrade to RHEL 8.
-
Technical support jointly provided by Alibaba Cloud and Red Hat.
For additional questions, see the Red Hat FAQ.
How do I upgrade from RHEL 7 to RHEL 8?
-
The RHEL instance meets the Red Hat Enterprise Linux Technology Capabilities and Limits.
-
Your RHEL instance is a RHEL 7 system from an Alibaba Cloud public image (with a RHEL 7 subscription) or a self-imported RHEL 7 system with an Alibaba Cloud RHEL 7 subscription.
Note
-
An Alibaba Cloud RHEL subscription provides licensed access to the software, security updates, and technical support for RHEL on Alibaba Cloud.
-
For a RHEL system with a subscription purchased directly from Red Hat, see Upgrading from RHEL 7 to RHEL 8.
-
Back up data by creating a snapshot to prevent data loss if the upgrade fails. See Create a snapshot.
-
Log on to the ECS instance as the root user.
See Connect to a Linux instance using Workbench.
Important
Root permissions are required for the upgrade.
-
Check whether your RHEL instance uses an Alibaba Cloud RHEL subscription.
rpm -q client-rhel7
-
If no response is returned, your system does not use an Alibaba Cloud RHEL subscription. Purchase a subscription first, then perform the upgrade.
-
If a response similar to client-rhel7-3.0-1.el7_9.noarch is returned, your system uses an Alibaba Cloud RHEL subscription. Proceed with the upgrade.

-
Prepare the upgrade environment.
-
Upgrade the RHEL system to the latest version and restart the system.
yum -y update
reboot
-
Install the Leapp upgrade tool.
yum -y install leapp leapp-rhui-alibaba --enablerepo="*"
-
Verify that Leapp is installed.
leapp --version
A response similar to leapp version xxx confirms Leapp is installed.
-
Perform a pre-upgrade check.
System configurations vary. Use the Leapp tool to run a pre-upgrade check and resolve any reported issues before upgrading.
-
Perform a pre-upgrade check.
-
Pre-upgrade to the latest version of RHEL 8.
leapp preupgrade --no-rhsm
-
Pre-upgrade to a specific target version. For example, upgrade RHEL 7 to RHEL 8.8.
leapp preupgrade --no-rhsm --target 8.8
Note
Run leapp preupgrade -h to view supported target versions.
-
View the pre-upgrade check results.
Leapp pre-upgrade check logs:
-
/var/log/leapp/leapp-preupgrade.log: Leapp tool logs
-
/var/log/leapp/leapp-report.txt: Pre-upgrade check report in text format
-
/var/log/leapp/leapp-report.json: Pre-upgrade check report in JSON format
If the pre-upgrade check fails, the failed items are displayed:

-
(Conditional) Handle pre-upgrade errors.
Check /var/log/leapp/leapp-report.txt for error messages and resolve them based on the Leapp tool's suggestions. Common errors by risk level:
-
high (inhibitor): Blocks the upgrade. Must be resolved before proceeding.
-
Case 1: Multiple kernel versions are installed on the system.
Risk Factor: high (inhibitor)
Title: Multiple devel kernels installed
Summary: DNF cannot produce a valid upgrade transaction when multiple kernel-devel packages are installed.
Remediation: [hint] Remove all but one kernel-devel packages before running Leapp again.
[command] yum -y remove kernel-devel-3.10.0-1160.11.1.el7
Solution: Uninstall old kernel packages using the command suggested by Leapp, for example, yum -y remove kernel-devel-3.10.0-1160.11.1.el7.
-
Case 2: Kernel modules that are not supported in RHEL 8 are loaded on the system.
Risk Factor: high (inhibitor)
Title: Leapp detected loaded kernel drivers which have been removed in RHEL 8. Upgrade cannot proceed.
Summary: Support for the following RHEL 7 device drivers has been removed in RHEL 8:
- floppy
Solution: Some modules, such as the floppy module in this example, are not supported in RHEL 8. Uninstall them:
rmmod floppy
-
Case 3: Non-standard sshd_config configuration
Risk Factor: high (inhibitor)
Title: Possible problems with remote login using root account
Summary: OpenSSH configuration file does not explicitly state the option PermitRootLogin in sshd_config file, which will default in RHEL8 to "prohibit-password".
Remediation: [hint] If you depend on remote root logins using passwords, consider setting up a different user for remote administration or adding "PermitRootLogin yes" to sshd_config.
If this change is ok for you, add explicit "PermitRootLogin prohibit-password" to your sshd_config to ignore this inhibitor
Solution:
-
In /etc/ssh/sshd_config, set PermitRootLogin to yes.
Note
PermitRootLogin defaults differ between RHEL 7 and RHEL 8:
-
Restart the sshd service:
systemctl restart sshd
-
Case 4: The acknowledgement file is not edited and confirmed.
Risk Factor: high (inhibitor)
Title: Missing required answers in the answer file
Summary: One or more sections in answerfile are missing user choices: remove_pam_pkcs11_module_check.confirm
For more information consult https://leapp.readthedocs.io/en/latest/dialogs.html
Remediation: [hint] Please register user choices with leapp answer cli command or by manually editing the answerfile.
[command] leapp answer --section remove_pam_pkcs11_module_check.confirm=True
Solution: Delete the unsupported pam module. Confirm deletion in the /var/log/leapp/answerfile file by setting confirm to True:
leapp answer --section remove_pam_pkcs11_module_check.confirm=True

-
high: Does not block the upgrade but must be resolved before or after the upgrade.
-
Case 1: Some packages cannot be installed.
Risk Factor: high
Title: Packages from unknown repositories may not be installed
Summary: 3 packages may not be installed or upgraded due to repositories unknown to leapp:
- python3-pyxattr (repoid: rhel8-CRB)
- rpcgen (repoid: rhel8-CRB)
- ustr (repoid: rhel8-CRB)
Remediation: [hint] In case the listed repositories are mirrors of official repositories for RHEL (provided by Red Hat on CDN) and their repositories IDs has been customized, you can change the configuration to use the official IDs instead of fixing the problem. You can also review the projected DNF upgrade transaction result in the logs to see what is going to happen, as this does not necessarily mean that the listed packages will not be upgraded. You can also install any missing packages after the in-place upgrade manually.
Solution: Install the missing packages manually after the upgrade.
-
Case 2: Some RHEL 7 packages are not upgraded.
Risk Factor: high
Title: Some RHEL 7 packages have not been upgraded
Summary: Following RHEL 7 packages have not been upgraded:
leapp-upgrade-el7toel8-0.18.0-1.el7_9
kernel-3.10.0-1160.92.1.el7
leapp-rhui-alibaba-1.0.0-1.el7_9
Please remove these packages to keep your system in supported state.
Solution: Remove these packages: yum remove leapp-upgrade-el7toel8-0.18.0-1.el7_9 kernel-3.10.0-1160.92.1.el7 leapp-rhui-alibaba-1.0.0-1.el7_9
-
medium: Does not block the upgrade but should be resolved to prevent potential issues.
Case: The pam_pkcs11 module in the PAM configuration will be removed.
Title: Module pam_pkcs11 will be removed from PAM configuration
Summary: Module pam_pkcs11 was surpassed by SSSD and therefore it was removed from RHEL-8. Keeping it in PAM configuration may lock out the system thus it will be automatically removed from PAM configuration before upgrading to RHEL-8. Please switch to SSSD to recover the functionality of pam_pkcs11.
Remediation: [hint] Configure SSSD to replace pam_pkcs11
Solution: Configure SSSD to replace the functionality of pam_pkcs11 to ensure authentication works correctly after the upgrade.
-
low: Minor impact. Should be resolved to ensure stable operation.
Case: SELinux will be set to permissive mode.
Risk Factor: low
Title: SElinux will be set to permissive mode
Summary: SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.
Remediation: [hint] Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the "/root/tmp_leapp_py3" SElinux warnings.
Solution: After the upgrade, verify no SELinux-related warnings exist, then reset SELinux to enforcing mode.
-
info: Informational. No action required. Review the report to understand changes during the upgrade.
Case: The release version in /etc/dnf/vars/releasever will be set to the current target version.
Risk Factor: info
Title: Release version in /etc/dnf/vars/releasever will be set to the current target release
Summary: On this system, Leapp detected "releasever" variable is either configured through DNF/YUM configuration file and/or the system is using RHUI infrastructure. To avoid issues with repofile URLs (when --release option is not provided) in cases where there is the previous major.minor version value in the configuration, release version will be set to the target release version (8.8). This will also ensure the system stays on the expected target version after the upgrade
No action is required.
-
Perform the upgrade.
-
Upgrade to the latest version of RHEL 8.
leapp upgrade --no-rhsm
-
Upgrade to a specific target version. For example, upgrade RHEL 7 to RHEL 8.8.
leapp upgrade --no-rhsm --target 8.8
A successful upgrade looks like this:

-
Restart the instance to boot into the new system.
reboot
-
Verify the upgrade result.
-
Run the cat /etc/redhat-release command to check whether the system version is updated.
-
Check the upgrade execution logs or reports for any errors.
-
Observe whether your application runs correctly on the RHEL 8 system.
-
(Conditional) Configure the RHEL source.
After the Leapp upgrade, the /etc/dnf/vars/releasever file locks the system to a specific minor version. For example, RHEL 8.8 points to https://xxxx/8.8/xxx. To access the latest RHEL 8 packages, delete the releasever file and rebuild the metadata cache.
rm -f /etc/dnf/vars/releasever
dnf clean all && dnf makecache
The repository source updates to https://xxxx/8/xxx, enabling automatic access to the latest RHEL 8 security patches and feature updates.
How do I upgrade from RHEL 8 to RHEL 9?
-
The RHEL instance meets the Red Hat Enterprise Linux Technology Capabilities and Limits.
-
Your RHEL instance is a RHEL 8 system from an Alibaba Cloud public image (with a RHEL 8 subscription) or a self-imported RHEL 8 system with an Alibaba Cloud RHEL 8 subscription.
Note
-
An Alibaba Cloud RHEL subscription provides licensed access to the software, security updates, and technical support for RHEL on Alibaba Cloud.
-
For a RHEL system with a subscription purchased directly from Red Hat, see Upgrading from RHEL 8 to RHEL 9.
-
Back up data by creating a snapshot to prevent data loss if the upgrade fails. See Create a snapshot.
-
Log on to the ECS instance as the root user.
See Connect to a Linux instance using Workbench.
Important
Root permissions are required for the upgrade.
-
Check whether your RHEL instance uses an Alibaba Cloud RHEL subscription.
rpm -qa |grep aliyun
-
If no response is returned, your system does not use an Alibaba Cloud RHEL subscription. Purchase a subscription first, then perform the upgrade.
-
If the response contains a minor version, such as rhel8.6, submit a ticket to obtain the latest RPM package, install it, then perform the upgrade.

Note
When running RHEL on Alibaba Cloud, the system accesses Red Hat software repositories through Alibaba Cloud's RHUI service. A minor-version-specific package, such as aliyun_rhel8.6-2.0-1.noarch, may prevent RHUI connections, blocking software updates and upgrades.
-
If a subscription package similar to aliyun_rhui_rhel8-2.0-3.x86_64 is returned, your system uses an Alibaba Cloud RHEL subscription. Proceed with the upgrade.

-
Prepare the upgrade environment.
-
Upgrade the RHEL system to the latest version and restart the system.
yum -y update
reboot
-
Install the Leapp upgrade tool.
yum -y install leapp leapp-rhui-alibaba --enablerepo="*"
-
Verify that Leapp is installed.
leapp --version
A response similar to leapp version xxx confirms Leapp is installed.
-
Perform a pre-upgrade check.
System configurations vary. Use the Leapp tool to run a pre-upgrade check and resolve any reported issues before upgrading.
-
Perform a pre-upgrade check.
-
systemctl stop systemd-resolved
systemctl disable systemd-resolved
-
Pre-upgrade to the latest version of RHEL 9.
leapp preupgrade --no-rhsm
-
Pre-upgrade to a specific target version. For example, upgrade RHEL 8 to RHEL 9.4.
leapp preupgrade --no-rhsm --target 9.4
Note
Run leapp preupgrade -h to view supported target versions.
-
View the pre-upgrade check results.
Leapp pre-upgrade check logs:
-
/var/log/leapp/leapp-preupgrade.log: Leapp tool logs
-
/var/log/leapp/leapp-report.txt: Pre-upgrade check report in text format
-
/var/log/leapp/leapp-report.json: Pre-upgrade check report in JSON format
If the pre-upgrade check fails, the failed items are displayed:

-
(Conditional) Handle pre-upgrade errors.
Check /var/log/leapp/leapp-report.txt for error messages and resolve them based on the Leapp tool's suggestions. Common errors by risk level:
-
high: Does not block the upgrade but must be resolved before or after the upgrade.
-
Case 1: Custom Leapp actors or files were detected.
Risk Factor: high
Title: Detected custom leapp actors or files.
Summary: We have detected installed custom actors or files on the system. These can be provided e.g. by third party vendors, Red Hat consultants, or can be created by users to customize the upgrade (e.g. to migrate custom applications). This is allowed and appreciated. However Red Hat is not responsible for any issues caused by these custom leapp actors. Note that upgrade tooling is under agile development which could require more frequent update of custom actors.
The list of custom leapp actors and files:
- /usr/share/leapp-repository/repositories/system_upgrade/common/files/rhui/alibaba/content.crt
- /usr/share/leapp-repository/repositories/system_upgrade/common/files/rhui/alibaba/key.pem
- /usr/share/leapp-repository/repositories/system_upgrade/common/files/rhui/alibaba/leapp-alibaba.repo
Related links:
- Customizing your Red Hat Enterprise Linux in-place upgrade: https://red.ht/customize-rhel-upgrade
Remediation: [hint] In case of any issues connected to custom or third party actors, contact vendor of such actors. Also we suggest to ensure the installed custom leapp actors are up to date, compatible with the installed packages.
Solution: Ensure custom actors are up to date and compatible with the Leapp tool. After the upgrade, verify system operation. See Customizing your Red Hat Enterprise Linux in-place upgrade.
-
Case 2: The GRUB2 configuration will be automatically updated during the upgrade.
Risk Factor: high
Title: GRUB2 core will be automatically updated during the upgrade
Summary: On legacy (BIOS) systems, GRUB2 core (located in the gap between the MBR and the first partition) cannot be updated during the rpm transaction and Leapp has to initiate the update running "grub2-install" after the transaction. No action is needed before the upgrade. After the upgrade, it is recommended to check the GRUB configuration.
Solution: After the upgrade, check the GRUB configuration to ensure the system starts correctly.
-
low: Minor impact. Should be resolved to ensure stable operation.
Case: SELinux is set to permissive mode.
Risk Factor: low
Title: SElinux will be set to permissive mode
Summary: SElinux will be set to permissive mode. Current mode: enforcing. This action is required by the upgrade process to make sure the upgraded system can boot without beinig blocked by SElinux rules.
Remediation: [hint] Make sure there are no SElinux related warnings after the upgrade and enable SElinux manually afterwards. Notice: You can ignore the "/root/tmp_leapp_py3" SElinux warnings.
Solution: After the upgrade, verify no SELinux-related warnings exist, then reset SELinux to enforcing mode.
-
info: Informational. No action required. Review the report to understand changes during the upgrade.
Case: Some target system repositories are excluded.
Risk Factor: info
Title: Excluded target system repositories
Summary: The following repositories are not supported by Red Hat and are excluded from the list of repositories used during the upgrade.
- rhui-codeready-builder-for-rhel-9-aarch64-rhui-rpms
- codeready-builder-for-rhel-9-aarch64-rpms
- codeready-builder-for-rhel-9-s390x-rpms
- codeready-builder-beta-for-rhel-9-ppc64le-rpms
- codeready-builder-for-rhel-9-x86_64-rpms
Remediation: [hint] If some of excluded repositories are still required to be used during the upgrade, execute leapp with the --enablerepo option with the repoid of the repository required to be enabled as an argument (the option can be used multiple times).
Solution: To enable excluded repositories during the upgrade, use the --enablerepo option.
-
Perform the upgrade.
-
Upgrade to the latest version of RHEL 9.
leapp upgrade --no-rhsm
-
Upgrade to a specific target version. For example, upgrade RHEL 8 to RHEL 9.4.
leapp upgrade --no-rhsm --target 9.4
A successful upgrade looks like this:

-
Restart the instance to boot into the new system.
reboot
-
Verify the upgrade result.
-
Run the cat /etc/redhat-release command to check whether the system version is updated.
-
Check the upgrade execution logs or reports for any errors.
-
Observe whether your application runs correctly on the RHEL 9 system.
-
(Conditional) Configure the RHEL source.
After the Leapp upgrade, the /etc/dnf/vars/releasever file locks the system to a specific minor version. For example, RHEL 9.4 points to https://xxxx/9.4/xxx. To access the latest RHEL 9 packages, delete the releasever file and rebuild the metadata cache.
rm -f /etc/dnf/vars/releasever
dnf clean all && dnf makecache
The repository source updates to https://xxxx/9/xxx, enabling automatic access to the latest RHEL 9 security patches and feature updates.
How do I upgrade from RHEL 9 to RHEL 10?
-
Back up data by creating a snapshot to prevent data loss if the upgrade fails. See Create a snapshot.
-
Log on to the ECS instance as the root user. See Connect to a Linux instance using Workbench.
Important
Root permissions are required for the upgrade.
Check whether your RHEL instance uses the Alibaba Cloud RHEL subscription:
-
Run rpm -qa |grep aliyun to check whether your RHEL instance uses an Alibaba Cloud RHEL subscription. If a subscription package similar to aliyun_rhui_rhel9-2.0-1.x86_64 is returned, your system uses an Alibaba Cloud RHEL subscription. Proceed with the upgrade.
-
Prepare the upgrade environment.
-
Upgrade the RHEL system to the latest version and restart the system.
yum -y update
reboot
-
Install the Leapp upgrade tool.
yum -y install leapp leapp-rhui-alibaba --enablerepo="*"
-
Verify that Leapp is installed. If a response similar to leapp version xxx is returned, Leapp is installed.
leapp --version
-
Perform a pre-upgrade check.
System configurations vary. Use the Leapp tool to run a pre-upgrade check and resolve any reported issues before upgrading.
-
Perform a pre-upgrade check for the latest version of RHEL 10.
leapp preupgrade --no-rhsm
Note
Run leapp preupgrade -h to view supported target versions.
-
View the pre-upgrade check results.
Leapp pre-upgrade check logs:
-
/var/log/leapp/leapp-preupgrade.log: Leapp tool logs.
-
/var/log/leapp/leapp-report.txt: Pre-upgrade check report in text format.
-
/var/log/leapp/leapp-report.json: Pre-upgrade check report in JSON format.
If the pre-upgrade check fails, specific failed items are displayed as shown in the following figure.
Check the log file for error messages and resolve them based on Leapp's recommendations. Resolve any inhibitor-level NIC errors — otherwise, the network may become unavailable after the upgrade.
If the inhibitor-level error "title": "Legacy network configuration found" is reported, run the suggested command, such as nmcli connection migrate /etc/sysconfig/network-scripts/ifcfg-eth0. Otherwise, the network may become unavailable after the upgrade.

-
(Conditional) Handle pre-upgrade errors.
Check /var/log/leapp/leapp-report.txt for error messages and resolve them based on Leapp's suggestions. Common errors by risk level:
-
high: Does not block the upgrade but must be resolved before or after the upgrade.
-
Case 1: Custom Leapp actors or files were detected.
-
Case 2: The GRUB2 configuration will be automatically updated during the upgrade.
-
low: Minor impact. Should be resolved to ensure stable operation.
-
Case: SELinux will be set to permissive mode.
-
Case: Some target system repositories are excluded.
-
Perform the upgrade. The following figure indicates a successful upgrade.
leapp upgrade --no-rhsm

-
Run the reboot command to restart the instance and boot into the new system.
-
Verify the upgrade result.
-
Run the cat /etc/redhat-release command to check whether the system version is updated.
-
Check the upgrade execution logs or reports for any errors.
-
Monitor your services on the RHEL 9 system to verify proper operation.
-
(Conditional) Configure the RHEL source.
After the Leapp upgrade, the /etc/dnf/vars/releasever file locks the system to a specific minor version. For example, RHEL 10.1 points to https://xxxx/10.1/xxx. To access the latest RHEL 10 packages, delete the releasever file and rebuild the metadata cache.
rm -f /etc/dnf/vars/releasever
dnf clean all && dnf makecache
The repository source updates to https://xxxx/10/xxx, enabling automatic access to the latest RHEL 10 security patches and feature updates.